Why the world keeps choosing Europe's privacy rules

Today, 172 countries have their own data protection laws, and most of them carry a clear influence of one European regulation: the General Data Protection Regulation. Melinee Kositwatanarerk, external PhD researcher, and Klaus Heine, Professor of Law and Economics, both affiliated with Erasmus School of Law and the Erasmus Center of Law and Digitalization, set out to explain why. Their answer combines two concepts borrowed from economics and organization theory: path dependence and network effects.

What is the GDPR, and why does it matter? 

The General Data Protection Regulation (GDPR), introduced by the EU in 2018, sets strict rules for how companies and organizations collect, store and use personal data, everything from your email address to your online shopping habits. It gives citizens rights, such as the right to know what data is held about them and to have it deleted. What makes the GDPR unusual is that it does not just apply within the EU. Companies outside Europe that want to do business with European customers, or simply process their data, often have to follow the same rules. Over time, many countries have gone a step further and copied the GDPR's approach into their own national laws. Kositwatanarerk and Heine wanted to understand the mechanism behind the broad adoption of this regulation. 

Two concepts: path dependence and network effects 

The GDPR's global influence is often explained through Anu Bradford's well-known concept of the "Brussels Effect," the idea that the sheer size of the EU market forces companies worldwide to comply with its rules. Kositwatanarerk and Heine add two other concepts to that picture: path dependence and network effects. 

Path dependence means that choices made in the past shape what is possible today, even if other alternatives exist. Once a certain path is taken, it becomes harder and harder to leave it. Network effects explain why: a system becomes more valuable, and more attractive to newcomers, the more people are already using it. "Path dependence and network effects offer a unique perspective that is distinct from the Brussels Effect. Rather than explaining the outcome, they illustrate the evolution of the GDPR and how it attracted others to become part of its network," Kositwatanarerk argues. 

Building the path of data protection 

The researchers trace this evolution through three phases. Before the 1990s, countries developed data protection laws independently, with little coordination between them. That changed with the EU's 1995 Data Protection Directive, the GDPR's predecessor, which began pulling other jurisdictions toward a shared European model. The GDPR then locked in that leading position. 

This pattern is familiar to other areas of life. Take the QWERTY keyboard, named after the first six letters on the top row. It was originally designed in the 1800s to prevent mechanical typewriters from jamming, not because it was the most efficient layout. Once typists everywhere had learned it, though, switching to a better-designed keyboard became too costly and inconvenient, even after the original jamming problem disappeared with newer machines.  

A similar story applies to Delaware, a small US state that has become the default choice for company registrations. In the early twentieth century, Delaware attracted businesses by offering flexible corporate laws and a specialized court system built solely to handle business disputes, making it an appealing place to incorporate. Once enough lawyers, courts and companies became specialized in Delaware's corporate law, staying became easier than switching elsewhere. The GDPR shows the same dynamic: once enough countries, companies and legal professionals had adapted to the European approach, switching to something else became increasingly costly. 

Why some alternatives never took off? 

Not every attempt at a global privacy standard succeeded. The APEC Privacy Framework, launched by Asia-Pacific countries in 2004, never became a serious rival to the GDPR. According to Kositwatanarerk, the reason lies in its design. "The APEC Privacy Framework was created differently from the GDPR. It is a non-binding framework that does not contain a complete set of data privacy standards, such as those set out in the GDPR." Without binding rules, the framework never built the kind of network that would draw others in. 

The Schrems Rulings 

The GDPR's leading position has faced real challenges too. Twice, Europe's highest court struck down agreements that allowed companies to transfer data between the EU and the United States, first an arrangement called Safe Harbor, then its successor, Privacy Shield. Both times, the court ruled that American privacy protections fell short of European standards. For Kositwatanarerk, this is not a sign of weakness but the opposite. "It highlights the very strong path dependence of the GDPR, as well as the EU's unilateral authoritative power to determine its path.  

However, the inconsistency between the European Commission and the Court of Justice of the European Union has led to confusion and uncertainty among businesses in both the United States and the EU regering the future direction of the GDPR. It is important for the EU to address these issues in the governance of the GDPR and find a way to signal legal certainty." she says. The EU alone decides who meets its bar, and it is willing to withdraw that approval, even from a major partner like the US, which only reinforces how central the European standard has become. 

Simplifying without weakening data protection 

Looking forward, the researchers argue that the GDPR may need to simplify to keep expanding, a direction reflected in the European Commission's proposed Digital Omnibus. In practice, simplification means reducing the administrative burden of compliance, such as easing some of the paperwork and procedural requirements companies and countries face, without changing the core rights citizens have over their data.  

That distinction matters: it is companies and governments trying to meet GDPR standards who would notice the difference, not individual citizens, whose underlying protections stay the same. Kositwatanarerk does not see this as a threat to citizens. "I do not think the simplification would undermine the protection of data subjects in the EU, rather it would help the GDPR to expand its network as more countries would be able to fulfil the requirements." 

Could the GDPR's standing ever break? 

Kositwatanarerk compares the GDPR's grip to that of a messaging app. "If a single user switched to another messenger, it would not affect the majority lock-in within WhatsApp. However, if the whole community simultaneously and collectively switched to another application, it would be possible to break WhatsApp's leading position." However, she sees no realistic prospect of that happening to the GDPR any time soon. 

Her closing message is aimed less at countries adopting European standards, and more at Brussels itself. "It is essential for those driving the GDPR to embrace a more global approach and welcome more contributions from its networking members," she says, a reminder that a rule born in Europe now belongs, in practice, to the world. 

PhD student
Professor
More information

Read the article here

Listen to the podcast here

Related content
The new research center ECLD combines legal expertise on digitalisation to clarify complex legislation and create societal impact.
Schaub, Heine, Quintavalla
Prifti, Demir and Krämer share insights about their upcoming book, which addresses the relationship between AI and law.
frontcover boek digital governance

Compare @count study programme

  • @title

    • Duration: @duration
Compare study programmes